MIPv4 Security Context Derivation via Access Point Name

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile internet protocol version 4 (MIPv4) signaling in interworking networks lacks robust security associations for multiple packet data network (PDN) connections, particularly in non-3GPP access networks, which compromises the security and consistency of IP connectivity.

Innovation Solution

A method and system are introduced to generate an extended master session key, creating a mobile internet protocol root key and security parameter index based on the access point name (APN), deriving unique mobile node home agent and foreign agent keys, and associating them with the security parameter index to establish a unique and secure MIPv4 connection for PDN connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security associations per IP connectivity are used in 3GPP networks to support multiple PDN connections, then multiple PDN connections are enabled, but the security associations are not robust and compromise security consistency

Engineering Contradiction:
Improvemultiple PDN connectionsVSAvoidsecurity association robustness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security association structure by introducing separate security contexts for each PDN connection. Instead of using a single security association for all connections, the system creates distinct security contexts (EPS security context and MIPv4 security context) for each PDN, ensuring that security parameters are uniquely derived per connection while maintaining overall system security consistency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by deriving security parameters locally for each specific PDN connection using the APN as a unique identifier. The MIPv4 security context is locally derived from the EPS security context using connection-specific parameters (APN, IP address), ensuring that each PDN connection has customized security parameters tailored to its specific requirements rather than using generic shared parameters.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If non-3GPP access networks use traditional MIPv4 protocol without 3GPP security enhancements, then network compatibility is maintained, but security and consistency of IP connectivity are compromised

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidIP connectivity security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism where the 3GPP AAA server acts as a mediator between non-3GPP access networks and the MIPv4 protocol. The AAA server performs EAP authentication to establish an EPS security context, then derives MIPv4-specific security parameters from this context. This intermediary process allows non-3GPP networks to use standard MIPv4 while incorporating 3GPP-level security through the AAA server's key derivation and distribution functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes security parameters by transforming the EPS security context into MIPv4-specific security parameters through a derivation process. The system changes the parameter representation from generic EPS security parameters to MIPv4-specific parameters (MIPv4 keys, SPI, authentication extensions) while maintaining the cryptographic strength of the original EPS security context. This parameter transformation enables compatibility with MIPv4 infrastructure while preserving 3GPP security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2327269B1Method and system for creating a mobile internet protocol version 4 connection
Publication Date: 2018.08.22 SAMSUNG ELECTRONICS CO LTD
  • EP2327269B1 patent drawingFigure 1
  • EP2327269B1 patent drawingFigure 2
  • EP2327269B1 patent drawingFigure 3

AI summary

A method for creating a unique and secure mobile internet protocol version 4 connection for a packet data network is provided. The method includes generating an extended master session key to create a mobile internet protocol root key. The method also includes creating a mobile internet protocol security parameter index based on the mobile internet protocol root key and an access point name. The method further includes deriving a mobile node home agent key based on the access point name. Furthermore the method includes associating the derived mobile node home agent key to the created security parameter index. Moreover the method includes providing the unique and secure mobile internet protocol version 4 connection to transfer data for the packet data network connectivity.